ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

Bush attacks European privacy regulations

Stephanie Olsen, CNET News.com CNet

Published: 28 Mar 2001 08:48 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Bush administration is pressing European regulators to weaken proposed privacy standards for consumers, saying that the current blueprint would make it difficult for U.S. financial institutions to conduct business abroad.

In a March 23 letter addressed to John Mogg, director general of the European Commission, the departments of Treasury and Commerce struck a note of worry about standard contract clauses proposed by the group for business agreements between U.S. and European companies.

Such contracts outline what companies can and can't do with consumer data in business deals across country lines. But a difficulty arises in the fundamental differences in consumer privacy protections in Europe and the United States. The European Union's privacy directive, for example, stipulates that consumers must have access to data collected about them and have the opportunity to destroy or change such data.

The United States' policy is more liberal, centring on the collection and resale of data from public records and giving consumers the ability to "opt out" of information sharing, privacy experts say. Because the EU has stricter privacy laws, US companies could run into problems in the exchange of such data across international borders.

"The debate is nearing a showdown, and the European Commission appears to be taking the tact that: 'We're going to play by our rules, and if US financial institutions want to do business in international markets covered by the EU, then they have to play by our rules,'" said Bill Bradway, co-founder of Meridien Research, which specialises on studying the impact of technology on financial institutions globally.

Last week's letter stated that the financial sector may be "adversely affected" by the EU's proposal and that the standard clauses "impose unduly burdensome requirements that are incompatible with real-world operations." These concerns were previously described in a joint Treasury-Commerce letter sent to the EU in February. Representatives from the EU office in Washington, DC, could not be immediately reached for comment.

The Internet plays an increasingly critical and complicated role in setting privacy standards. Because capturing data over the Internet is standard practice for many companies, including financial institutions, companies could run into roadblocks if they have to treat data from European customers differently from those in the United States. "In order to do business in Europe, financial services companies are going to have to comply with this much, much stricter privacy provision of the EU directive," said Debra Pierce, an attorney with the Electronic Frontier Foundation (EFF).

The EU's proposal would affect the largest financial institutions, including JP Morgan, Merrill Lynch and Morgan Stanley Dean Witter, because they are operating overseas or have plans to do so.

Within the letter, the departments of Commerce and Treasury urged the commission to give the parties involved more time to find an adequate solution. The letter suggests potential conflicts could arise if stipulations in the standard clauses fail to match guidelines financial institutions are implementing in accordance with the Gramm-Leach-Bliley Act of 1999, which mandates consumer privacy protections.

The Bliley Act requires financial institutions, including insurance companies, brokerages and banks, to let customers opt out of potential data-sharing practices among those three parties. Privacy experts say that the EU directive is much more strict. Also at issue is what's known as "safe harbour," which doesn't cover financial institutions. Safe harbour is an arrangement negotiated by the Department of Commerce and the EU in which companies agree to abide by a set of guidelines dealing with the transfer of data, for example, between countries with strict privacy protections to those with more lax policies.

The safe harbour applies to large commercial companies operating globally, such as Coca-Cola or McDonald's. Only a small number of companies have signed up, however. Those provisions are less stringent that the contract standards. For example, they allow companies to provide some reasons why customer information can be shared without consent, privacy experts say. Therefore, standard contract clauses could not only impose harsher privacy standards on financial institutions than the Bliley Act; they could also levy stronger restrictions than are placed on companies operating under safe harbour provisions. "The whole other can of worms is the jurisdiction question. How far can another country reach in another country's business?" asked EFF's Pierce.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
39 out of 81 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Pre-Sales Consultant, Leading Business Solutions provider, Asset Suite

You will be responsible for taking on presales efforts globally, excluding the Americas. With headquarters in the United States, two offices in ...

Technical Autor- Media and Entertainment

The content produced will be utilised internally, globally and by third parties, so some experience with localisation and validation processes will ...

Technical Services Representative / 1st Line Support London Microsoft / Network - Support

Candidates must be eligible to work within the EU. Currently, We have offices in London, United States, Canada and Belgium. Technical Services ...

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme